Data Protection

Last updated: January 1, 2025

Cally Desk handles call recordings, customer information, and business data on your behalf. Here's exactly how we store it, protect it, and give you control over it.

1. Our Commitment to Data Protection

We treat data protection as a core feature, not an afterthought. Every architectural decision is reviewed through the lens of customer privacy and security.

2. Data We Process on Your Behalf

  • Call recordings and transcripts
  • Customer information collected by your AI receptionist
  • Chat logs from your website widget
  • Booking and appointment data

3. Data Processing Agreement

Cally Desk acts as the data processor and you, the customer, act as the data controller. A signed DPA is available on request to dpo@callydesk.com.

4. Where Your Data is Stored

Production data is stored on servers located in North America. Data residency in the EU is available on Pro plans on request.

5. Retention and Deletion

Default retention for call recordings is 90 days. Account and business data is retained for the life of your account. You may request deletion at any time by emailing dpo@callydesk.com.

6. GDPR Compliance

For EU data subjects we rely on legitimate interest and contractual necessity as our lawful bases for processing. Data subjects have rights of access, rectification, erasure, restriction, portability, and objection.

7. CCPA Compliance

California consumers have the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.

8. Security Measures

We employ encryption at rest (AES-256) and in transit (TLS 1.2+), strict role-based access controls, full access logging, and regular third-party penetration testing.

9. Breach Notification

In the unlikely event of a data breach affecting your data, we commit to notifying you within 72 hours of discovery.

10. Third-Party Sub-processors

  • Twilio — calls and SMS
  • Stripe — payments
  • Google — calendar integrations
  • Supabase — database
  • Vercel — hosting

11. Contact Our Data Protection Team

Email our Data Protection Officer at dpo@callydesk.com.

Questions about our policies? Contact us.